Skip to content

ssl_cert: Allow forcing IPv4 or IPv6 - #11012

Open
IshanA2007 wants to merge 1 commit into
Icinga:masterfrom
IshanA2007:feature/ssl-cert-force-ipv-9979
Open

IshanA2007 wants to merge 1 commit into
Icinga:masterfrom
IshanA2007:feature/ssl-cert-force-ipv-9979

Conversation

@IshanA2007

Copy link
Copy Markdown

The check_ssl_cert plugin supports -4/-6 to force IPv4 or IPv6, but the
ssl_cert CheckCommand had no way to pass them through.

As pointed out in the issue thread, the established pattern in the ITL is that
commands wrapping dual-stack-capable plugins provide their own documented
switches
on top of vars.check_ipv4/check_ipv6 (see dig, ssh, tcp).
This follows the dig CheckCommand exactly:

  • ssl_cert_ipv4 / ssl_cert_ipv6 map to the plugin's -4 / -6 flags.
  • Both also feed vars.check_ipv4 / vars.check_ipv6, so the ipv4-or-ipv6
    template that ssl_cert already imports picks the matching address family
    instead of handing the plugin an address of the other family.
  • Both are documented in doc/10-icinga-template-library.md.

This supersedes #9978, which used an ssl_-prefixed variable name, added no
documentation, and did not set vars.check_ipv[46].

Verified with icinga2 daemon -C and by running the daemon against a stub
plugin; the rendered command lines are:

check_ssl_cert -4 -H 127.0.0.1 -p 443     # ssl_cert_ipv4 = true
check_ssl_cert -6 -H ::1 -p 443           # ssl_cert_ipv6 = true
check_ssl_cert -H 127.0.0.1 -p 443        # neither set (unchanged)

fixes #9979

The check_ssl_cert plugin supports -4/-6 to force IPv4 or IPv6, but
the ssl_cert CheckCommand had no way to pass them, unlike most other
CheckCommands that wrap plugins with IPv4/IPv6 switches (e.g. dig,
ssh, tcp). Add ssl_cert_ipv4 and ssl_cert_ipv6 following that same
established pattern, and document them in the ITL docs.

refs Icinga#9979
@cla-bot

cla-bot Bot commented Sep 2, 2026

Copy link
Copy Markdown

Thank you for your pull request. Before we can look at it, you'll need to sign a Contributor License Agreement (CLA).

Please follow instructions at https://icinga.com/company/contributor-agreement to sign the CLA.

After that, please reply here with a comment and we'll verify.

Contributors that have not signed yet: @IshanA2007

Details
  • If you've already signed a CLA, it's possible we don't have your GitHub username or you're using a different email address. Please contact us if you think this is the case.

  • If you signed the CLA as a corporation, your GitHub username may not have been submitted to us. Please reach out to the responsible person in your organization.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ssl_cert: Allow forcing IPv4 or IPv6 check

1 participant